A flaw was found in the Netfilter subsystem in the Linux kernel. The sctp_mt_check did not validate the flag_count field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading to a crash or information disclosure.
Version | Score | Severity | Vector String |
---|---|---|---|
3.1 | 6.1 | Medium | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L |
Product | Vendor | Version |
---|---|---|
Red Hat Enterprise Linux 7 | Red Hat | <= 5.15.* |
Red Hat Enterprise Linux 8 | Red Hat | >= 22.0.0, < 22.2.10.16 |
Red Hat Enterprise Linux 9 | Red Hat | fe75e8a0c20127a8dc95704f1a7ad6b82c9a0ef8 |
Red Hat Enterprise Linux 9 | Red Hat | < 2024.3.55417 |
Red Hat Enterprise Linux 6 | Red Hat | < 101.0.4951.64 |
Red Hat Enterprise Linux 9 | Red Hat | n/a |
Red Hat Enterprise Linux 7 | Red Hat | n/a |
Red Hat Enterprise Linux 8 | Red Hat | < 10.0.19045.3208 |